Infinite loop Affecting com.rabbitmq:amqp-client package, versions [,5.37.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.49% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-COMRABBITMQ-20562151
  • published7 Oct 2026
  • disclosed6 Oct 2026
  • creditNotAFlightRisk

Introduced: 6 Oct 2026

NewCVE-2026-106121  (opens in a new tab)
CWE-835  (opens in a new tab)

How to fix?

Upgrade com.rabbitmq:amqp-client to version 5.37.0 or higher.

Overview

Affected versions of this package are vulnerable to Infinite loop in JSONReader.string() and JSONReader.skipWhiteSpace() in com.rabbitmq.tools.json, neither of which treats CharacterIterator.DONE as a terminator, so the string scanner appends that sentinel without bound and the line comment scanner spins in place. A user able to publish to the RPC request queue can exhaust the heap or pin a thread at full CPU indefinitely, by sending one JSON-RPC message that ends inside a string or a // comment. This requires the application to use the JSON-RPC over AMQP tooling in com.rabbitmq.tools.jsonrpc with the default DefaultJsonRpcMapper, and the condition is not confined to servers, since a client parsing a response from a JSON-RPC service fails the same way.

CVSS Base Scores

version 4.0
version 3.1